Description
In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller.



This vulnerability allows an authenticated device to escalate its permissions and bypass the strict boundaries of its assigned updates. Under normal operation, a device should be restricted strictly to the specific firmware artifacts explicitly assigned to it. However, this flaw enables any authenticated device to bypass this restriction and download any firmware artifact within the same tenant.



This is not an authentication bypass; the requesting device must possess valid credentials for its respective tenant. Instead, the issue stems from a flaw in object-level authorization validation.



A related, lower-severity helper issue exists in the listing software modules artifacts metadata endpoint. This endpoint does not enforce assignment checks, enabling an authenticated device to list and enumerate available firmware artifacts, which can facilitate targeted exfiltration using the main download authorization bypass.
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Eclipse hawkBit versions up to 1.0.3 contain a flaw in the Direct Device Integration controller that allows an authenticated device to bypass object‑level authorization checks. A device that holds valid credentials for its tenant can request and download any firmware artifact belonging to the same tenant, even those not assigned to it. This capability enables unauthorized firmware exfiltration and could potentially be leveraged for malicious firmware deployment, though the CVE payload does not explicitly state downgrades or other active attacks.

Affected Systems

The affected product is Eclipse hawkBit from the Eclipse Foundation, specifically versions 1.0.3 and earlier.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authenticated device credentials and occurs within the same tenant, constituting an intra‑tenant privilege escalation that relies on insufficient object‑level authorization controls.

Generated by OpenCVE AI on July 30, 2026 at 17:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade hawkBit to the latest available version that removes the object‑level authorization flaw.
  • If an upgrade cannot yet be applied, adjust the firmware download endpoint to enforce object‑level checks so that only artifacts explicitly assigned to a device are returned.
  • Revoke or limit the firmware download privileges granted to device accounts, ensuring they only possess the minimum necessary rights.
  • If the Direct Device Integration controller is not required in your deployment, disable or remove it to eliminate the attack surface.
  • Implement monitoring of download logs to detect anomalous or unauthorized firmware download attempts.

Generated by OpenCVE AI on July 30, 2026 at 17:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse hawkbit
Vendors & Products Eclipse
Eclipse hawkbit

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allows an authenticated device to escalate its permissions and bypass the strict boundaries of its assigned updates. Under normal operation, a device should be restricted strictly to the specific firmware artifacts explicitly assigned to it. However, this flaw enables any authenticated device to bypass this restriction and download any firmware artifact within the same tenant. This is not an authentication bypass; the requesting device must possess valid credentials for its respective tenant. Instead, the issue stems from a flaw in object-level authorization validation. A related, lower-severity helper issue exists in the listing software modules artifacts metadata endpoint. This endpoint does not enforce assignment checks, enabling an authenticated device to list and enumerate available firmware artifacts, which can facilitate targeted exfiltration using the main download authorization bypass.
Title Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration
Weaknesses CWE-284
CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-07-22T18:58:48.011Z

Reserved: 2026-07-21T10:01:44.585Z

Link: CVE-2026-16454

cve-icon Vulnrichment

Updated: 2026-07-22T18:58:43.381Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:15:12Z

Weaknesses